Triage an APK for bounty-worthy issues
Upload or pull an APK, run the 12-phase scan, and ask the AI agent for the most promising exploit chain.
RevDroid runs a 12-phase static analysis on your own machine, then an AI agent reasons over the results to build verifiable exploit chains. The APK never leaves your machine.
1 / 8
A self-hosted, AI-assisted Android APK security analyzer. A local agent runs a 12-phase static scan on your machine; an AI agent turns findings into verifiable exploit chains.
All decompilation and scanning run on a Node agent on your machine, bound to 127.0.0.1. APK bytes never leave your machine; only findings and small code snippets reach the AI layer.
Unpack, framework, signing, resources, code, secrets, trackers, files, binaries, packer detection, behaviour, and strings. Each phase streams to the dashboard live.
A per-project AI agent tracks bug-bounty hypotheses as multi-step chains: hypothesis, steps with status, and impact, seeded from canonical Android attack templates. Chains, not checklists.
Detects and adapts to Flutter, React Native, Xamarin, Unity, and native Android apps, including detected ABIs.
Finds hardcoded API keys and credentials for common cloud and SaaS providers, plus private keys and OAuth tokens.
Flags debuggable, allowBackup, cleartext traffic, exported components, deep links, and network security config.
ELF hardening checks (NX, PIE, RELRO, stack canary, stripped symbols), packer and obfuscator detection, certificate and signature analysis, tracker detection across 40+ SDKs, and behaviour signals.
Connect Android devices over USB or Wi-Fi, inspect device security posture, browse installed apps, view the live screen with remote input, and pull an installed APK straight into a project.
Hunters who want speed to a valid finding and signal over noise, with the target app kept private to their own machine.
Consultants running mobile assessments who need repeatable coverage and evidence, including code snippets, for a report.
In-house teams reviewing their own Android builds for secrets, misconfigurations, and risky components before release.
Teams that self-host a shared Android-security tool, with Google sign-in and per-conversation AI cost visibility.
Running, in 4 steps.
Start the Node agent on your machine. It generates a one-time pairing token and listens on 127.0.0.1:8071; paste the token into the dashboard.
Upload an APK file, or pull an installed package off a connected Android device over ADB. APKs are de-duplicated by SHA-256.
The agent unpacks the APK and runs 12 analysis phases, streaming each result to the dashboard as it completes.
Open the per-project AI chat. It reads your scan data through the agent, proposes multi-step exploit chains, and tracks verification steps.
Where it earns its place.
Upload or pull an APK, run the 12-phase scan, and ask the AI agent for the most promising exploit chain.
Scan an internal APK for hardcoded secrets, exported components, cleartext traffic, and weak crypto before it ships.
Assess Flutter, React Native, Xamarin, Unity, or native apps, with the framework and ABIs detected up front.
Work intentionally vulnerable apps and let the AI agent explain why a finding matters and how the steps chain together.
How RevDroid compares.
| vs. | RevDroid | Alternative |
|---|---|---|
| Cloud APK scanners | Decompiles and scans on your own machine; the APK never leaves it. | Typically require uploading the APK to a hosted service. |
| Checklist-style static scanners | A 12-phase pipeline plus an AI agent that connects findings into verifiable, multi-step exploit chains. | A flat list of isolated findings, without reasoning about how they connect. |
| Manual reverse engineering | Automates unpacking and a dozen analysis passes, then adds an AI copilot that tracks hypotheses across a project. | Decompiling by hand and grepping through smali, which is slow and easy to miss things in. |
Common questions about RevDroid.